Image Ninja – Convert Images to WebP & AVIF on Upload Security & Risk Analysis

wordpress.org/plugins/image-ninja

Automatically convert JPEG and PNG images to WebP and AVIF formats during upload to optimize your WordPress site’s performance.

40 active installs v1.0.1 PHP 7.2+ WP 5.0+ Updated May 24, 2025
avifimage-conversionmediaoptimize-imageswebp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Image Ninja – Convert Images to WebP & AVIF on Upload Safe to Use in 2026?

Generally Safe

Score 100/100

Image Ninja – Convert Images to WebP & AVIF on Upload has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'image-ninja' plugin v1.0.1 exhibits a strong security posture. The absence of any identified attack surface points, such as AJAX handlers, REST API routes, shortcodes, or cron events, significantly reduces the potential for external exploitation. Furthermore, the code signals are overwhelmingly positive, with no dangerous functions, no raw SQL queries (all prepared statements), no file operations, and no external HTTP requests. The presence of nonce and capability checks, while limited in number, indicates an awareness of security best practices for input validation and authorization.

The taint analysis revealing zero flows with unsanitized paths, regardless of severity, is a particularly strong indicator of secure coding. The vulnerability history being entirely clear of CVEs further reinforces the perception of a well-maintained and secure plugin. While the output escaping rate at 85% is good, it's the only area where a minor improvement could be made, though it doesn't represent an immediate critical risk given the overall lack of attack vectors.

In conclusion, the 'image-ninja' plugin v1.0.1 appears to be a very secure plugin with no immediate exploitable vulnerabilities detected. Its strengths lie in its minimal attack surface and the absence of critical code vulnerabilities. The lack of any historical vulnerabilities is a significant positive. The only minor point of attention would be to ensure the remaining 15% of outputs are also properly escaped to achieve a perfect score, but this is not a pressing security concern at this time.

Key Concerns

  • Output escaping not 100%
Vulnerabilities
None known

Image Ninja – Convert Images to WebP & AVIF on Upload Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Image Ninja – Convert Images to WebP & AVIF on Upload Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
11 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped13 total outputs
Attack Surface

Image Ninja – Convert Images to WebP & AVIF on Upload Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_initincludes\Admin\AdminSettings.php:8
actionadmin_initincludes\Admin\AdminSettings.php:9
actionadmin_noticesincludes\Admin\AdminSettings.php:13
actionadmin_noticesincludes\Admin\AdminSettings.php:124
filterattachment_fields_to_editincludes\Admin\MediaLibrary.php:6
filterwp_handle_upload_prefilterincludes\Core\ImageConverter.php:8
actioninitincludes\i18n.php:6
Maintenance & Trust

Image Ninja – Convert Images to WebP & AVIF on Upload Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 24, 2025
PHP min version7.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Image Ninja – Convert Images to WebP & AVIF on Upload Developer Profile

Nitin Singh

1 plugin · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Image Ninja – Convert Images to WebP & AVIF on Upload

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Image Ninja – Convert Images to WebP & AVIF on Upload